PT-2021-14362 · Jquery+1 · Jquery-Validation+1
Alvaro Muñoz
+1
·
Published
2021-01-13
·
Updated
2023-08-31
·
CVE-2021-21252
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
jquery-validation versions prior to 1.19.3
Description:
The issue concerns the jQuery Validation Plugin, which provides drop-in validation for existing forms. It contains one or more regular expressions that are vulnerable to ReDoS (Regular Expression Denial of Service). This vulnerability was discovered and reported by GitHub team member Erik Krogh Kristensen.
Recommendations:
For versions prior to 1.19.3, update to version 1.19.3 to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable regular expressions until a patch is applied.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Jquery-Validation